Palo Alto's CSO: Your Security Strategy Is Outdated. Here's How to Build One That's AI-Proof

Jesper Bork Olsen, Chief Security Officer for Northern Europe at Palo Alto Networks, explains why your current security strategy is built for threats that no longer exist. With 20+ years managing security at scale from NATO to NotPetya incident response to advising Fortune 500 CISOs, Jesper reveals the gap between resilience (the floor) and anti-fragility (the framework that wins). He shows why organizations need to embrace disruption rather than just survive it, and what makes one vendor chosen over another when every competitor claims identical features: the ability to turn threat landscape volatility into your competitive advantage. Jesper's pattern: when complexity explodes, he builds frameworks that separate signal from noise and connect security directly to business outcomes. At Palo Alto, he works across Northern Europe advising CISOs on the specific shifts required for AI-era threat landscapes where access-to-impact now happens in under 60 seconds. Key Insights: ■■ Resilience is the floor, not the ceiling. You need controls before, during, and after incidents. But mature compliance frameworks fail when process dependencies aren't mapped to digital systems. Perfect technology can coexist with fragile operations. ■■ AI accelerates both attackers and defenders exponentially. Threat actors use AI to optimize attack velocity and evasion. Your security operations team cannot respond at sub-60-second attack speeds without new architecture, tooling, and decision frameworks. ■■ The Imagine-Invest-Improve framework turns anti-fragility from theory into practice. Imagine phase stresses assumptions with tabletop exercises. Invest phase splits budget 80-20 for core resilience and high-risk innovation. Improve phase harvests every failure as learning. ■■ Data recovery after ransomware breaks AI models silently. Restoring encrypted datasets without understanding AI training data dependencies reintroduces bias and degrades performance over time. Most organizations have zero process for this. ■■ Three strategic investment areas now dominating: observability and visibility into what's running inside AI systems, integration security as AI agents multiply and create new attack surfaces, and data security through purpose-led data segmentation at creation point. Timestamps: 00:01 Welcome and the resilience crisis 01:35 Jesper's journey: military police to NATO to Maersk to Palo Alto 07:47 Why mature security strategies are designed for outdated threats 09:30 Is it a tech problem or a strategy problem? 10:01 The CEO who only learned after being breached 11:14 Anti-fragility vs resilience: what's the actual difference? 13:35 How AI exponentially compounds attack velocity and complexity 14:35 The business AI vs cyber AI gap nobody's prepared for 18:45 Attacks that move from access to impact in 60 seconds 20:22 Introducing the Imagine-Invest-Improve framework 23:00 The Imagine phase: strategic anticipation through tabletop exercises 23:59 The Invest phase: 80-20 budget allocation for anti-fragility 25:17 The Improve phase: harvesting failures as learning 26:28 Applying anti-fragility in operational technology heavy environments 29:47 Timeline and practical examples of the Imagine phase 32:21 The flywheel effect: agile sprints and security feedback loops 33:05 How Northern Europe vs US enterprises approach security strategy 35:37 Getting budget approved: the argument that works with CFOs 36:14 AI security investment math and what auditors ask 38:34 Why data set restoration breaks AI model performance silently 40:26 The rule of thumb for AI security spending 42:54 Four hottest strategic investment areas in cybersecurity 44:18 Integration security and the web of agent dependencies 45:58 The agent exchange layer: preparing legacy systems for AI agents 47:27 What security service companies should double down on 49:50 Data security and purpose-led data segmentation 50:31 Which security skills AI makes irrelevant vs more valuable 52:49 Why military professionals gravitate toward security leadership 55:54 Train as you fight: lessons from NotPetya incident response 56:46 What excites Jesper about the next three years of security 57:04 Quantum as the great equalizer against AI-accelerated threats 59:37 Closing remarks and thank you Follow Jesper Borg-Alsson:   / jbolsen   Follow Chirag Khanijau:   / chirag-khanijau   Links: Palo Alto Networks: https://www.paloaltonetworks.com Flywheelr: https://www.flywheelr.com BrandStori: https://brandstori.ai CXO Spotlight:   / cxospotlight   Listen on Spotify: https://open.spotify.com/show/4xVy5IP... Listen on Apple: https://podcasts.apple.com/us/podcast... #CyberSecurity #AntiFragility #CISO #AISecurityFramework #NotPetya #DataSecurity #IntegrationSecurity #VulnerabilityManagement #IncidentResponse

The Uncomfortable Truth About AI “Reasoning” | World Science Festival
▶︎

The Uncomfortable Truth About AI “Reasoning” | World Science Festival

TypeScript in Express – TypeScript Tutorial
▶︎

TypeScript in Express – TypeScript Tutorial

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

The PROBLEM with Capitalism - Smarter Every Day 316
▶︎

The PROBLEM with Capitalism - Smarter Every Day 316

Architecture, AI agents, and product empathy with Robert C. Martin
▶︎

Architecture, AI agents, and product empathy with Robert C. Martin

Digging into Pickaxe Mountain | feat. Ilan Berman
▶︎

Digging into Pickaxe Mountain | feat. Ilan Berman

The Heartbreaking Atrocity of The Ukraine War (And Why You Should Care) - James Verini
▶︎

The Heartbreaking Atrocity of The Ukraine War (And Why You Should Care) - James Verini

Digital Asset Treasuries Under Pressure, IMF Warns of Tokenization Risks | Bloomberg Crypto 4/7/2026
▶︎

Digital Asset Treasuries Under Pressure, IMF Warns of Tokenization Risks | Bloomberg Crypto 4/7/2026

Real-Time WebSockets Course | Build a Live Sports Dashboard with Node.js & PostgreSQL
▶︎

Real-Time WebSockets Course | Build a Live Sports Dashboard with Node.js & PostgreSQL

URGENT UPDATE - Iran War Expert: A Mass Casualty Attack Is Coming! | Robert Pape
▶︎

URGENT UPDATE - Iran War Expert: A Mass Casualty Attack Is Coming! | Robert Pape

How to Restore a Broken Relationship
▶︎

How to Restore a Broken Relationship

Build a Full-Stack GenAI Project in 4 Hours (FastAPI, React, Supabase)
▶︎

Build a Full-Stack GenAI Project in 4 Hours (FastAPI, React, Supabase)

Jfrog | Jfrog Artifactory | Jfrog Artifactory Tutorial | Artifactory Tutorial | Intellipaat
▶︎

Jfrog | Jfrog Artifactory | Jfrog Artifactory Tutorial | Artifactory Tutorial | Intellipaat

Mayor Zohran Mamdani on Socialism, Politics & NYC | The Weekly Show with Jon Stewart
▶︎

Mayor Zohran Mamdani on Socialism, Politics & NYC | The Weekly Show with Jon Stewart

Full Archon Guide - Build AI Coding Harnesses That Actually Ship (LIVE)
▶︎

Full Archon Guide - Build AI Coding Harnesses That Actually Ship (LIVE)

4 Hours of Deep Focus Music for Studying - Concentration Music For Deep Thinking And Focus
▶︎

4 Hours of Deep Focus Music for Studying - Concentration Music For Deep Thinking And Focus

Most Valuable Skill of 2026: Managing AI Agents
▶︎

Most Valuable Skill of 2026: Managing AI Agents

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
▶︎

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra
▶︎

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

🚨 LIVE: Mohammad Marandi - Iran War Now Entering Most Dangerous Phase
▶︎

🚨 LIVE: Mohammad Marandi - Iran War Now Entering Most Dangerous Phase